PT-2026-61006 · Xrdp+1 · Xrdp+1
CVE-2026-44178
·
Published
2026-07-08
·
Updated
2026-08-18
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
xrdp versions prior to 0.10.6.1
Description
A heap-based buffer overflow exists in the virtual channel forwarding mechanism. The process uses a fixed-size buffer without adequate bounds checking when forwarding data from a remote client to the internal channel server. An authenticated remote attacker can send a specially crafted virtual channel message that exceeds the buffer capacity, causing heap memory corruption. This can lead to a denial of service or arbitrary code execution with the privileges of the xrdp process.
Recommendations
Update to version 0.10.6.1.
Exploit
Fix
DoS
Heap Based Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Red Os
Xrdp